Skip to content
TORNLIFE More

Weav3rs compromised?

Started by poor [1532735] on in General Discussion.

10 replies · 829 views · thread synced · 8 days ago · View on torn.com
About this thread

Posts archived: 11 / 11 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
11
Discussion span
→
People posting
9
Likes on archived posts
45
Authority score
52 / 100
Historical score
23 / 100
Story score
55 / 100
Engagement score
68 / 100

Most-liked replies

poor [1532735]

Please refer to this post for any questions on why weav3rs is down

please do not message weav3r as he has a job and a life and hundreds of messages won’t go answered

https://www.torn.com/forums.php#/p=threads&f=67&t=16469591&b=0&a=0&start=300&to=26839599

Lady_White [2676391]

Service Disruption

 

Weav3r is currently at work so has asked me to take a look at the issues being faced right now. It looks like there has been a security issue with a dependency that the site is built on. There is no reason to suspect this was Torn related, and the data on the server looks mostly fine, other than the redirects, but I have outstanding concerns we have addressed for now. After a quick chat, he has removed the DNS records to the server temporarily to prevent traffic being directed to the server - this is likely to remain in place for at least several hours, and until we know more about the issue.

 

I did attempt to close only the impacted frontend for the project, but we seen other errors in the process (unrelated to security, just functionality), so it seems better to be cautious for now, so this is going to impact script users too. It continues to operate the "worker" component to fetch updates, so you may still see API calls being made - this is expected.

 

Please refrain from messaging Weav3r about it for the moment please, he is getting a lot of messages and any statements that need releasing will be done here and on the Discord.

From sent thread

Mentions: TornW3B: Bazaars, RW, & Profit Tracking

Beerstein [1322136]

I only gave public, sounds like it was a dependency issue though. There's next to 0 risk with public key, I get a service worth using, and if someone from torn targets it for torn benefits they'll get permafedded, not too worried with the public key as it give them 0 info they couldn't obtain without it.

Ohadik [424017] Wiki Contributor

Tin foil hats all around. 

 

A web server goes offline and the first thing that springs to your mind is it's been hacked. Everything in the cloud nowadays has made people forget about the 90's and 2000's when servers would blow a hard drive and be offline all afternoon. Nobody assumed someone hacked anything; they just automatically knew that they'd have to look up their pokemon's available movesets later.